Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-008/ |
|
History
Thu, 30 Jul 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Phoenixcontact
Phoenixcontact charx Sec-3000 Phoenixcontact charx Sec-3050 Phoenixcontact charx Sec-3100 Phoenixcontact charx Sec-3150 |
|
| Vendors & Products |
Phoenixcontact
Phoenixcontact charx Sec-3000 Phoenixcontact charx Sec-3050 Phoenixcontact charx Sec-3100 Phoenixcontact charx Sec-3150 |
Thu, 30 Jul 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised. | |
| Title | Missing authentication for MQTT Broker | |
| First Time appeared |
Phoenix Contact
Phoenix Contact charx Sec 3000 Phoenix Contact charx Sec 3050 Phoenix Contact charx Sec 3100 Phoenix Contact charx Sec 3150 |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:o:phoenix_contact:charx_sec_3000:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3050:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3100:*:*:*:*:*:*:*:* cpe:2.3:o:phoenix_contact:charx_sec_3150:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Phoenix Contact
Phoenix Contact charx Sec 3000 Phoenix Contact charx Sec 3050 Phoenix Contact charx Sec 3100 Phoenix Contact charx Sec 3150 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-07-30T06:47:04.767Z
Reserved: 2026-05-05T10:48:08.225Z
Link: CVE-2026-44090
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T09:15:04Z
Weaknesses